Enter your email address below and subscribe to our newsletter

Kaspersky uncovers new Mirage Kitten malware used in cyber-espionage campaign

Share your love

Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The findings were revealed at its annual Kaspersky Cyber Security Weekend for the Middle East, Turkiye and Africa (META). The malicious tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.

The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organisations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, aviation organisations in Pakistan, telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.

The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioural similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots. It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim’s machine, as if it originated from inside the victim’s network. This lets them slip past network defences and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.

While the initial access vector remains unclear in most cases, Kaspersky GReAT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organisation in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods. The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.

“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa. Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts. Given the persistence and sophistication of these techniques, organisations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,”says Omar Amin, senior security researcher at Kaspersky GReAT.

More details available on Securelist.com.

To stay protected from Mirage Kitten and other APT’s, organisations are advised to follow these best practices: 

  • Remain highly vigilant against the deployment of Mirage Kitten toolset, including NightLedger, ArcBridge and BridgeHead tunneling tools. 
  • To protect the company against a wide range of threats, use solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, investigation and the response capabilities of EDR and XDR for organisations of any size and industry. Depending on your current needs and available resources, you can choose the most relevant product tier and easily migrate to another one if your cybersecurity requirements are changing.
  • Adopt managed security services by Kaspersky such as Compromise AssessmentManaged Detection and Response (MDR) and / or Incident Response, covering the entire incident management cycle – from threat identification to continuous protection and remediation. They help to protect against evasive cyberattacks, investigate incidents and provide additional expertise even if a company lacks cybersecurity workers.
  • Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation. Kaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.

//Staff writer